Legal

Privacy Policy

Last updated: October 6, 2026

This Privacy Policy explains how COSTTRAIL INC (“we”, “us”) handles information when you use Files2BI, including the website at files2bi.com and the Files2BI web application (together, the “Service”).

1. The short version

  • Cloud mode: files you upload are stored encrypted in Amazon Web Services in the United States, are visible only to your workspace, and are deleted when you delete them.
  • Browser-Private mode: files stay on your computer and the search index is kept in your browser. To build the index, the text of your files is sent to us, masked, and turned into search vectors by Amazon Bedrock; it is not stored on our servers. When you ask a question, the relevant (masked) passages and your question are sent to produce the answer.
  • Teammates you invite share your workspace's files and token balance; each person's chat history stays private.
  • We do not sell personal information and we do not use your files or questions to train AI models.

2. Who is responsible

For personal information about you as an account holder, COSTTRAIL INC is the data controller. For the contents of files you upload, you control what you upload and we process it on your behalf to provide the Service. Questions, access requests or complaints: support@costtrail.io. Mailing address: COSTTRAIL INC, 1900 Pleasant Street, Noblesville, Indiana 46061-0813, USA.

3. Information we collect

CategoryExamplesSource
Account informationname, email, company (optional), password (stored only as a salted hash by Amazon Cognito)You, during sign-up
Authentication and sessionsession tokens, IP address, user-agent, sign-in timestampsAutomatically on use
Files you upload (Cloud mode)the files themselves, text, tables, figures and form fields extracted from them, search indexes, summaries and suggested questionsYou
Questions and answersyour questions, the answers and the sources cited, kept as your private chat history; saved queries; feedback you give on answersYou
Workspace datafolders, dashboards and charts, settings, team members and pending invitationsYou and your teammates
Billing informationtoken purchases and balances; card details are handled by our payment partner, never by usYou; Lemon Squeezy
Usage recordswhich actions used tokens and how many, timings and error logsAutomatically on use
Support communicationsmessages you send through the contact form or by emailYou

4. How we use information

  • Provide, maintain and secure the Service, your account and your team's workspace.
  • Read, index and analyse the files you upload so you can ask questions about them, and answer those questions with citations.
  • Meter token usage, process purchases, and send transactional emails (verification codes, password resets, team invitations).
  • Detect and prevent fraud, abuse and security incidents.
  • Improve reliability and performance using aggregated, de-identified metrics.

We do not look at the contents of your files except where you ask us to for support, or where the law requires it.

5. Legal bases

  • Contract: to deliver the Service you signed up for.
  • Legitimate interests: security, fraud prevention and service improvement, balanced against your rights.
  • Legal obligation: tax, accounting and responding to lawful requests.
  • Consent: optional communications, which you can withdraw at any time.

6. Automatic masking of sensitive data

When you upload a file, the Service detects and masks card and bank account numbers, IBAN, IFSC and routing numbers, card security codes and expiry dates, government ID numbers (such as SSN, Aadhaar, PAN and passport numbers), email addresses, phone numbers, postal addresses, dates of birth and medical record numbers before the extracted content is stored, indexed or sent to an AI model. Masked values are not kept in your workspace's index and are not shown in answers; card and account numbers keep their last four digits. Detection uses pattern and checksum rules and Amazon Comprehend / Amazon Comprehend Medical. Person and company names are not masked. Masking is provided on a best-effort basis: detection is automatic and may not catch every instance, so do not rely on it as your only safeguard for highly sensitive files (see section 7 of our Terms of Service). Your original uploaded file is kept unchanged, private to your workspace.

7. AI processing

Answers, summaries, image descriptions and table extraction use AI models hosted on Amazon Bedrock (Anthropic Claude and Amazon Titan models); scanned pages and tables are read with Amazon Textract. Only what is needed for each task is sent — for a question, your question and the relevant passages of your files. These services process requests on an inference-only basis and do not use your content to train models. We do not train models on your data.

8. Who we share information with

  • Amazon Web Services (US) — hosting, file storage, databases, sign-in (Amazon Cognito), email (Amazon SES) AI processing (Amazon Bedrock, Amazon Textract) and sensitive-data detection (Amazon Comprehend, Amazon Comprehend Medical).
  • Lemon Squeezy (US) — our payment partner and merchant of record for token purchases.
  • Your teammates — members of your workspace see its files, folders, dashboards and saved queries, and the team list.
  • Professional advisors — legal, accounting and audit firms, under confidentiality.
  • Authorities — when required by law or to protect rights, safety or property.

We do not sell personal information and we do not share it for cross-context behavioural advertising.

9. International transfers

The Service is hosted in the United States (AWS US East). If you use it from outside the US, your information and the files you upload are transferred to and processed in the US, with appropriate safeguards where required.

10. Retention and deletion

Files and everything extracted from them are kept until you delete them or close your account. Deleting a file removes it, its extracted content and its search index from the Service; backup copies of the file are purged within 30 days. Chat history, saved queries and dashboards are deleted when you delete them or close your account. Account information is kept for the life of your account and a reasonable period afterwards for legal, tax and audit purposes; token usage and billing records are retained for up to 7 years.

11. Security

We use TLS 1.2+ in transit, encryption at rest, private storage that is not publicly reachable, per-workspace access checks on every request, least-privilege access, and monitoring. No method of transmission or storage is perfectly secure; we will notify affected customers of a confirmed incident without undue delay.

12. Your rights

Depending on where you live, you may have rights to access, correct, delete, restrict or object to processing, port your data, and withdraw consent. California residents have additional rights under the CCPA/CPRA. To exercise any right, email support@costtrail.io. We respond within the timeframes required by law.

13. Children

The Service is not directed to children under 16, and we do not knowingly collect their personal information.

14. Cookies and browser storage

We use strictly necessary cookies and browser storage to keep you signed in and remember preferences such as light or dark mode. In Browser-Private mode, the search index (masked passages and their search vectors) is kept in your browser's storage on your device; your files stay in the folder you chose. We do not use advertising cookies.

15. Changes

We may update this Policy. Material changes will be posted here with a new “Last updated” date and, where appropriate, communicated by email or in-product notice.

16. Contact

COSTTRAIL INC, 1900 Pleasant Street, Noblesville, Indiana 46061-0813, USA. Privacy: support@costtrail.io.